Junglewise Threat Intelligence

CVE-2026-5309: GitLab Enterprise Edition authorization bypass in Virtual Registry Cleanup Policy API

CVE-2026-5309 · Severity: medium · CVSS 5.4 · Published 2026-06-25

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition contains a security flaw that allows an authorized user to view or change the cleanup settings for another group's virtual registry. This could lead to unauthorized modifications of data retention policies or the exposure of internal configuration settings. Organizations should update to the latest patched versions to ensure proper isolation between different user groups.

Technical details

An authorization bypass vulnerability (CWE-639) exists in the Virtual Registry Cleanup Policy API of GitLab EE. The flaw stems from insufficient authorization checks when accessing or modifying cleanup policies, allowing an authenticated attacker to manipulate settings belonging to other groups by providing a user-controlled key. The vulnerability affects versions 18.6 through 18.11.5, 19.0.x before 19.0.3, and 19.1.x before 19.1.1. It has been remediated in versions 18.11.6, 19.0.3, and 19.1.1.

Affected products

  • GitLab GitLab Enterprise Edition 18.6 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1

Timeline

  • 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, and 18.11.6
  • 2026-06-25: advisory: NVD published the CVE record

References

Related threats